What went wrong with Coldcard #BTC

Coldcard, the Bitcoin‑only hardware wallet made by Canadian firm Coinkite, is facing one of its biggest security incidents after a firmware bug quietly weakened how some devices generate seed phrases.

The thefts began on Friday, July 30, and have continued in waves since. On‑chain analysts have tracked multiple exploits, with losses now estimated at 1,000–1,300 $BTC (roughly $70–$90 million) across more than 1,000 addresses. The largest bursts moved hundreds of $BTC in under an hour, and researchers say the attacks may be ongoing as of this writing.

Attackers exploited a flaw dating back to March 2021, causing some Coldcard units to fall back on a predictable software random number generator instead of the device’s hardware RNG when creating new wallets. That reduced the randomness (entropy) in the seed, making it possible for an attacker to reconstruct likely seed phrases offline and derive the private keys without ever touching the physical device.

This has prompted many, including the likes of Binance Founder CZ, to rethink the safety of hardware wallets and self-custody in general